HomeSecurityPrestaShop fixes a bug that allows any backend user to...

PrestaShop fixes a bug that allows any backend user to delete databases

Open-source e-commerce platform PrestaShop has released a new version that addresses a critical vulnerability that allows any back-office user to write, update, or delete SQL databases regardless of their permissions.

PrestaShop

Back-office users are those who have access to the administrative interface of the website, including the owner, administrators, sales representatives, customer support agents, order processors, data entry staff, and others.

Each user's permissions are configured to only allow them access to the information and functions necessary for their role, which is a critical security feature of PrestaShop.

See also: Evasive Panda: Uses MgBot malware to target international NGOs in China

The critical (CVSS v3.1 score: 9.9) flaw, CVE-2023-30839, allows any user, regardless of their permissions, to make unauthorized modifications to the e-commerce database, potentially causing significant damage or downtime to affected businesses.

The flaw, which has no mitigation, affects all PrestaShop installations from version 8.0.3 and older.

While the need to have a user account on the vulnerable website somewhat mitigates the vulnerability, considering that online stores often use large teams to handle orders, the flaw carries the risk of allowing fraudsters or disgruntled employees to cause damage.

Additionally, it opens up a larger attack surface for hackers, who can now compromise any user account on PrestaShop-based e-commerce sites and potentially introduce malicious code and backdoors or gain access to the SQL database.

Backdoor injections via website databases are a stealthy attack tactic that Sucuri recently reported is gaining attention from hackers , primarily targeting WordPress websites .

The software vendor addressed this with the release of versions 8.0.4 and 1.7.8.9, released yesterday, in which all PrestaShop website owners are advised to upgrade as soon as possible.

The open-source e-commerce platform has also fixed two other vulnerabilities in its latest release, namely CVE-2023-30535 (CVSS v3.1: 7.7, “high risk”) and CVE-2023-30838 (CVSS v3.1: 8.0, “high risk”).

See also: Cisco discloses XSS zero-day vulnerability in server management tool

PrestaShop fixes a bug that allows any backend user to delete databases

The first is an arbitrary file reading issue that gives unauthorized users access to critical information. The second is an XSS injection issue that can compromise any HTML element on the website and is triggered without any interaction.

It is important to apply available security updates as soon as possible, as hackers are always looking for vulnerabilities in large platforms like PrestaShop.

See also: Ukrainian sold data of 300 million citizens to Russians

In July 2022, the e-commerce solutions provider warned its users that hackers targeted the platform by exploiting a zero-day vulnerability to carry out SQL injections on PrestaShop-based sites.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS